We are seeking a GRC & Compliance Automation Engineer to join our team working with a global leader in the innovation and development of life-changing vision and eye care products.
EPAM provides end-to-end SDLC services spanning architecture, analytics, software engineering, quality assurance, business intelligence, delivery management, and production support. Key engagement domains include Data (AWS-based Data Lake), Digital, Manufacturing, and ChatGPT (Azure-based intelligent agents across all client divisions).
In this role, you will build and operate the three Information Assurance agents and the evidence lake that power the compliance automation and certification runway, turning manual audit work into continuous, automated evidence collection. Production experience with security for AI Agents and Agentic AI Architecture is an absolute must.
Responsibilities
- Build and run the three IA agents: Continuous Audit Evidence, Trust Center / SafeBase Response, and Agentic AI Control Mapping
- Stand up the evidence lake and automated control collectors
- Drive 70% or more of controls to automatically evidenced status
- Support the certification runway: SOC 2 Type 2, then ISO 42001, then SOX-AI
- Automate audit collection across domains using Python/API integrations and the Power Platform
Requirements
- 4+ years of experience in GRC, compliance automation, or security engineering
- Background in GRC platforms and control frameworks (SOC 2, ISO, SOX)
- Proficiency in automation using Python, REST APIs, and audit/evidence collectors
- Capability to build and operate agents in either Azure or AWS (e.g., Copilot Studio / Azure AI, or AWS Bedrock Agents / Lambda) to automate compliance and evidence collection
- Expertise in AI Security and LLM security
- Competency in the Power Platform (Power Automate, Power Apps)
- Skills in translating control requirements into automated, repeatable evidence pipelines
- Excellent command of written and spoken English (B2+ level)
Nice to have
- Familiarity with AI governance frameworks (ISO 42001, NIST AI RMF)
- Understanding of CISO-level responsibilities and practices
- Relevant certifications (e.g., CISA, CRISC)